ID

VAR-201809-0105


CVE

CVE-2018-12168


TITLE

Intel Computing Improvement Program Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2018-010704

DESCRIPTION

Privilege escalation in file permissions in Intel Computing Improvement Program before version 2.2.0.03942 may allow an authenticated user to potentially execute code as administrator via local access. Intel Computing Improvement Program is a software improvement program application program of Intel Corporation. This program is used to collect computer function usage information, component usage information, operating system information, etc. A local attacker could exploit this vulnerability to elevate privileges and execute code as an administrator

Trust: 1.8

sources: NVD: CVE-2018-12168 // JVNDB: JVNDB-2018-010704 // VULHUB: VHN-122100 // VULMON: CVE-2018-12168

AFFECTED PRODUCTS

vendor:intelmodel:computing improvement programscope:ltversion:2.2.0.03942

Trust: 1.8

sources: JVNDB: JVNDB-2018-010704 // NVD: CVE-2018-12168

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-12168
value: HIGH

Trust: 1.0

NVD: CVE-2018-12168
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201809-612
value: HIGH

Trust: 0.6

VULHUB: VHN-122100
value: HIGH

Trust: 0.1

VULMON: CVE-2018-12168
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-12168
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-122100
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-12168
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-122100 // VULMON: CVE-2018-12168 // JVNDB: JVNDB-2018-010704 // CNNVD: CNNVD-201809-612 // NVD: CVE-2018-12168

PROBLEMTYPE DATA

problemtype:CWE-732

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-122100 // JVNDB: JVNDB-2018-010704 // NVD: CVE-2018-12168

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201809-612

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201809-612

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-010704

PATCH

title:INTEL-SA-00165url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00165.html

Trust: 0.8

title:Intel Computing Improvement Program Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=84871

Trust: 0.6

sources: JVNDB: JVNDB-2018-010704 // CNNVD: CNNVD-201809-612

EXTERNAL IDS

db:NVDid:CVE-2018-12168

Trust: 2.6

db:JVNDBid:JVNDB-2018-010704

Trust: 0.8

db:CNNVDid:CNNVD-201809-612

Trust: 0.6

db:VULHUBid:VHN-122100

Trust: 0.1

db:VULMONid:CVE-2018-12168

Trust: 0.1

sources: VULHUB: VHN-122100 // VULMON: CVE-2018-12168 // JVNDB: JVNDB-2018-010704 // CNNVD: CNNVD-201809-612 // NVD: CVE-2018-12168

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00165.html

Trust: 1.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-12168

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-12168

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/732.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-122100 // VULMON: CVE-2018-12168 // JVNDB: JVNDB-2018-010704 // CNNVD: CNNVD-201809-612 // NVD: CVE-2018-12168

SOURCES

db:VULHUBid:VHN-122100
db:VULMONid:CVE-2018-12168
db:JVNDBid:JVNDB-2018-010704
db:CNNVDid:CNNVD-201809-612
db:NVDid:CVE-2018-12168

LAST UPDATE DATE

2024-11-23T23:12:03.665000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-122100date:2019-10-03T00:00:00
db:VULMONid:CVE-2018-12168date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-010704date:2018-12-20T00:00:00
db:CNNVDid:CNNVD-201809-612date:2019-10-23T00:00:00
db:NVDid:CVE-2018-12168date:2024-11-21T03:44:41.270

SOURCES RELEASE DATE

db:VULHUBid:VHN-122100date:2018-09-12T00:00:00
db:VULMONid:CVE-2018-12168date:2018-09-12T00:00:00
db:JVNDBid:JVNDB-2018-010704date:2018-12-20T00:00:00
db:CNNVDid:CNNVD-201809-612date:2018-09-13T00:00:00
db:NVDid:CVE-2018-12168date:2018-09-12T19:29:01.807